Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Arturxr
Explorer

Export logs from var / log / messages in cef format

hello, is it possible to export logs from / var / log / messages in cef format to siem system?
It is known that it is not possible to do it through cp_log_export, and with sk102995 there is no way to change the format to cef.
0 Kudos
7 Replies
G_W_Albrecht
Legend
Legend

See sk122323: Log Exporter - Check Point Log Export :

Formats: Syslog, Splunk, CEF, LEEF, Generic, JSON, LogRhythm, RSA

cp_log_export add name <Name> [domain-server <Name or IP address of Domain Server>] target-server <HostName or IP address of Target Server> target-port <Port on Target Server> protocol {udp | tcp} format {syslog | splunk | cef | leef | generic | json | logrhythm | rsa}

CCSE CCTE CCSM SMB Specialist
0 Kudos
(1)
Arturxr
Explorer

Hello, I looked at this sk, there is no way to export specifically / var / log / messages, the manufacturer says the same

0 Kudos
G_W_Albrecht
Legend
Legend

Look into this discussion about getting logs from security gateway (not traffic related logs, but for example, /var/log/messages) from syslog:

https://community.checkpoint.com/t5/General-Topics/Syslog-messages-from-the-Security-Gateway/td-p/31...

 

CCSE CCTE CCSM SMB Specialist
0 Kudos
CarlosDias
Contributor

Hi,

I am running R81.10 JHF 110 and only see this command on the Manager.

What about the Gateways?

Regards

0 Kudos
Vincent_Bacher
Advisor
Advisor

Firewall logs are sent to the manager or log host. Therefore this command is mangement/logserver only.

and now to something completely different - CCVS, CCAS, CCTE, CCCS, CCSM elite
0 Kudos
CarlosDias
Contributor

Hi,

Thanks for your answer, but since from the gateways I can send syslog messages directly to other syslog servers apart the manager I imagined I could send them directly in CEF format.

One further question if you can help.

I managed to configure the manager to send in CEF format, mas the amount of information is huge, and I dont see no changes either I configure it to send all messages or just emergency.

Is there a way to configure the CEF level of messages?

Regards

0 Kudos
PhoneBoy
Admin
Admin

Log Exporter can export Security Logs (not from /var/log/messages) in CEF format.
You can send OS logs to the Security Logs as @G_W_Albrecht mentions, which can then be exported as CEF.
However, I suspect the result of that may not be what you’re after.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events